First published: Fri Aug 03 2018(Updated: )
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | >=7.6.0.0<=7.6.3.0 | |
Ibm Maximo For Aviation | =7.6.0.0 | |
Ibm Maximo For Aviation | =7.6.1.0 | |
Ibm Maximo For Aviation | =7.6.2.0 | |
Ibm Maximo For Aviation | =7.6.2.1 | |
Ibm Maximo For Aviation | =7.6.3.0 | |
Ibm Maximo For Life Sciences | =7.6.0.0 | |
Ibm Maximo For Nuclear Power | =7.6.0.0 | |
Ibm Maximo For Oil And Gas | =7.5.0.0 | |
Ibm Maximo For Oil And Gas | =7.6.0.0 | |
Ibm Maximo For Transportation | =7.6.1.0 | |
Ibm Maximo For Transportation | =7.6.2.0 | |
Ibm Maximo For Transportation | =7.6.2.1 | |
Ibm Maximo For Transportation | =7.6.2.2 | |
Ibm Maximo For Transportation | =7.6.2.3 | |
Ibm Maximo For Transportation | =7.6.2.4 | |
Ibm Maximo For Utilities | =7.6.0.0 | |
IBM SmartCloud Control Desk | =7.6.0.0 | |
IBM SmartCloud Control Desk | =7.6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1524 is a vulnerability in IBM Maximo Asset Management 7.6 through 7.6.3 that allows a remote intruder to gain administrator access to the system.
CVE-2018-1524 has a severity of 8.8 (critical).
IBM Maximo Asset Management 7.6 through 7.6.3, IBM Maximo For Aviation 7.6.0.0 through 7.6.3.0, IBM Maximo For Life Sciences 7.6.0.0, IBM Maximo For Nuclear Power 7.6.0.0, IBM Maximo For Oil And Gas 7.5.0.0 and 7.6.0.0, IBM Maximo For Transportation 7.6.1.0 through 7.6.2.4, IBM Maximo For Utilities 7.6.0.0, and IBM SmartCloud Control Desk 7.6.0.0 and 7.6.0.1 are affected.
Yes, there is a fix available. Please refer to the IBM support document in the references for more information.
More information about CVE-2018-1524 can be found in the IBM X-Force ID and the IBM support document in the references.